|
|
|
Ask HN: Is Web Penetration Testing Worth It?
|
|
3 points
by intesar
1503 days ago
|
|
One of our clients is forcing us to share a web penetration testing report. We do all kinds of security testing ourselves, but they wouldn't accept our reports. The client policy requires the vendors to share a third-party report. I spoke to a bunch of penetration testing companies. It seems they do basic tests and charge ridiculously high. My question is, is it worth doing web penetration testing? Has anyone found it helpful beyond the checklist need? |
|
However, there are many teams who either don't have the knowledge/expertise, or the available time, to do the testing themselves. This is where "buying it off the shelf" can come in handy.
Then, there are teams that are completely clueless when it comes to application security, and even the most basic scan by any of these pen testing vendors will find very obvious security defects, which is absolutely valuable for them to learn about. This is the minimum bar that we should hold software application developers to, and there are many who don't even meet this without the assistance of reports from pen testing vendors. Scary, but true.
So, YMMV.